TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

A Gov.uk site dedicated to porn?

188 点作者 asadhaider超过 3 年前

24 条评论

bongoman37超过 3 年前
It seems to have been taken offline now. Here&#x27;s the archive[1] link for uh.. research. Obviously, NSFW.<p>[1]: <a href="https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20211125154944&#x2F;http:&#x2F;&#x2F;charts.dft.gov.uk&#x2F;" rel="nofollow">https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20211125154944&#x2F;http:&#x2F;&#x2F;charts.dft...</a>
benbristow超过 3 年前
Since the site is down - <a href="https:&#x2F;&#x2F;archive.ph&#x2F;tCgnL" rel="nofollow">https:&#x2F;&#x2F;archive.ph&#x2F;tCgnL</a>
notatoad超过 3 年前
Wow.<p>I thought this was going to be about some sneaky exploit where they&#x27;d manage to get a gov.uk to forward links to porn or something. But no, it&#x27;s really a whole subdomain just taken over by some sketchy porn site.<p>I&#x27;m wondering if the porn site operators even know it&#x27;s happening? Seems the most likely thing is the DfT had a site at that URL, hosted on AWS. And then they shut it down without removing the DNS record and Amazon assigned that IP to somebody else.
评论 #29343545 未加载
评论 #29343572 未加载
评论 #29347705 未加载
nneonneo超过 3 年前
The site in question is charts.dft.gov.uk (VERY NSFW). It resolves to the CNAME charts.dft.gov.uk.s3-website-eu-west-1.amazonaws.com, which is quite clearly hosting a porn site of some kind.<p>I suppose there&#x27;s a few possible explanations here: (1) the original site was hosted on S3, and at some point the bucket was dropped and someone else picked it up, (2) it was originally hosted on S3 and the bucket got hacked, (3) someone with access to the DNS has decided to go rogue and point it at a somewhat-legit-looking but fake domain. If there are historical DNS records floating around it might help to narrow down what happened here.
评论 #29343373 未加载
评论 #29349405 未加载
Firefishy超过 3 年前
Sub-domain takeover attack. The sub-domain was CNAME&#x27;ed to a S3 bucket and the S3 bucket had likely been deleted. The porn purveyor, re-created a new S3 bucket with pr0n.<p>A scanner that would have caught the vulnerability: <a href="https:&#x2F;&#x2F;tech.ovoenergy.com&#x2F;how-we-prevented-subdomain-takeovers-and-saved-000s&#x2F;" rel="nofollow">https:&#x2F;&#x2F;tech.ovoenergy.com&#x2F;how-we-prevented-subdomain-takeov...</a><p>Or a grey hat scanner for finding sub-domains vulnerable to takeover: <a href="https:&#x2F;&#x2F;github.com&#x2F;m4ll0k&#x2F;takeover" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;m4ll0k&#x2F;takeover</a>
评论 #29347330 未加载
qeternity超过 3 年前
&gt; This site is hosted on a Raspberry Pi 4B in the author&#x27;s living room (behind the couch).<p>Holding up quite well despite HN frontpage. I love what a bit of caching can do.<p>EDIT: appears I jinxed it. I get the allure of hosting something in your home, but these days when you can get a decent VPS for $10&#x2F;yr it doesn’t really make sense.
评论 #29343658 未加载
评论 #29343321 未加载
评论 #29343310 未加载
评论 #29343817 未加载
评论 #29343290 未加载
评论 #29343296 未加载
评论 #29343328 未加载
评论 #29343394 未加载
tentacleuno超过 3 年前
&gt; Visit [redacted], and you’ll be redirected to a subdomain for EU exit hauliers - except the site isn’t there. Instead it’s a WordPress login page. There’s no username field and we feel confident that a brute force attack would be super effective!<p>&gt; Elsewhere we have the Department for Transport careers page, which sort of does what it says. Clicking on the ‘see all vacancies’ button will redirect you to the civil service jobs site. This isn’t weird in itself, what is weird is that it uses t.co - Twitter’s redirection and domain obscuring tool to do it. Don’t ask us why, we have no idea why they would do this.<p>This sounds like someone inexperienced with the system is somehow managing it. How can you use a t.co link for... this? I&#x27;m surprised this edit got past anyone.<p>EDIT: Redacted the link just to be on the safe side. It&#x27;s in the article if anyone&#x27;s curious.
评论 #29343375 未加载
necovek超过 3 年前
December 2018 snapshot refers to Department of Transport: <a href="https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20181227091013&#x2F;http:&#x2F;&#x2F;charts.dft.gov.uk&#x2F;" rel="nofollow">https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20181227091013&#x2F;http:&#x2F;&#x2F;charts.dft...</a>.<p>The CNAME of charts.dft.gov.uk.s3-website-eu-west-1.amazonaws.com still works, but the reverse DNS of that IP is simply s3-website-eu-west-1.amazonaws.com: I am not sure how does one gain control of an s3-website subdomain when &quot;abandoned&quot; (bucket name only?), but someone did.<p>So the scenario someone described below is pretty likely: DoT drops it, and drops AWS use of the name, but leaves the DNS record in. I wouldn&#x27;t attribute this to anyone in the DoT.<p>It would still require intentional action to do so, though, so I wonder if anyone has any clue how do people find out about spurious, unused S3 subdomains that still have DNS pointing at them? Scan the entire internet for domains pointing to s3-website, and check AWS API to see if it&#x27;s available? Or did someone run into this by accident and decided to poke fun at it while earning some cash along the way?
评论 #29343503 未加载
arpa超过 3 年前
A great read in a tongue-in-cheek british style, a welcome change of pace for mind and eyes!
rbanffy超过 3 年前
&gt; Best of British Porn? Not Quite<p>That&#x27;s not a very fair assessment. The same way as it&#x27;s difficult to find British dishes better than, say, minced beef and onion pie, it&#x27;s challenging to find authentically British porn that&#x27;s better than this govermnent office provides its people. We should commend the Tory government for its dedication.
评论 #29345182 未加载
belval超过 3 年前
The title should be changed to reflect that the article is actually about .gov.uk domain being used for non-governmental websites.
评论 #29343207 未加载
dddavid超过 3 年前
Both my own site (on a Pi behind the couch) and the gov site were subjected to the hug of death. I&#x27;ve moved thecrow.uk onto a VPS for now and it&#x27;s back up. Hurray!
iso1631超过 3 年前
British Government Porn? That the one where we all get screwed by Rishi in the budget?
评论 #29344576 未加载
osrec超过 3 年前
Looks like someone forgot to delete a DNS entry after decommissioning a server. Bad on behalf of gov.uk, however you&#x27;d think AWS would at least auto-delete the CNAME (charts.dft.gov.uk.s3-website-eu-west-1.amazonaws.com) after the server was released, so that it points to nothing...
Terry_Roll超过 3 年前
I don&#x27;t know if this is laziness and ineptitude on the govt&#x27;s part or not. You see the design team for UK gov websites have been getting a lot of attention and praise for their efforts, the most recent being here just ten days ago on the subject of check boxes: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=29238968" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=29238968</a> .<p>Now anyone with a rudimentary handle of the English language would probably have noticed the misspelling of carcasses on the blogpost <a href="https:&#x2F;&#x2F;designnotes.blog.gov.uk&#x2F;2021&#x2F;11&#x2F;15&#x2F;letting-users-tick-a-none-checkbox&#x2F;" rel="nofollow">https:&#x2F;&#x2F;designnotes.blog.gov.uk&#x2F;2021&#x2F;11&#x2F;15&#x2F;letting-users-tic...</a> and Yorwba highlighted this on 17 November 2021 as seen in the comments. The team duly acknowledge this as seen with the updated image here <a href="https:&#x2F;&#x2F;designnotes.blog.gov.uk&#x2F;wp-content&#x2F;uploads&#x2F;sites&#x2F;53&#x2F;2021&#x2F;11&#x2F;Design-System-filter-question-with-titles-620x414.jpg" rel="nofollow">https:&#x2F;&#x2F;designnotes.blog.gov.uk&#x2F;wp-content&#x2F;uploads&#x2F;sites&#x2F;53&#x2F;...</a> and the original misspelling can still be seen here <a href="https:&#x2F;&#x2F;designnotes.blog.gov.uk&#x2F;wp-content&#x2F;uploads&#x2F;sites&#x2F;53&#x2F;2021&#x2F;11&#x2F;Filter-question-and-question-gov-uk-design-system-example.jpg" rel="nofollow">https:&#x2F;&#x2F;designnotes.blog.gov.uk&#x2F;wp-content&#x2F;uploads&#x2F;sites&#x2F;53&#x2F;...</a><p>Anyway, it would seem their commenting system will not allow links to be posted to them or they choose to ignore links or didn&#x27;t understand the comment posted when comments like &quot;<a href="https:&#x2F;&#x2F;www.bing.com&#x2F;search?q=plural+of+carcass" rel="nofollow">https:&#x2F;&#x2F;www.bing.com&#x2F;search?q=plural+of+carcass</a>&quot; come through to them which is metadata for the type of filtering being employed on their comments section.<p>I think its worth looking at their design principles which can be seen here <a href="https:&#x2F;&#x2F;www.gov.uk&#x2F;guidance&#x2F;government-design-principles" rel="nofollow">https:&#x2F;&#x2F;www.gov.uk&#x2F;guidance&#x2F;government-design-principles</a> &quot;#1 Start with user needs Service design starts with identifying user needs. If you don’t know what the user needs are, you won’t build the right thing. Do research, analyse data, talk to users. Don’t make assumptions. Have empathy for users, and remember that what they ask for isn’t always what they need.&quot;<p>It would seem Grant Shapps Secretary of State for Transport is perhaps actually meeting the public&#x27;s needs or maybe its what he thinks of the public. Are we solitary handy manipulators of parts of the body?
globalise83超过 3 年前
Hope Hacker News didn&#x27;t set fire to the couch!
mlaretallack超过 3 年前
I am now taking bets on how long it will last.<p>&#x27;This site is hosted on a Raspberry Pi 4B in the author&#x27;s living room (behind the couch)&#x27;
评论 #29343297 未加载
评论 #29343549 未加载
necovek超过 3 年前
Btw, it would have been hilarious if the site owner had set up LetsEncrypt SSL certificate for the charts.dft.gov.uk domain :)
max1cc超过 3 年前
Hug of death! <a href="https:&#x2F;&#x2F;archive.md&#x2F;tCgnL" rel="nofollow">https:&#x2F;&#x2F;archive.md&#x2F;tCgnL</a>
adav超过 3 年前
I’m only disappointed that the squatting site didn’t conform to GDS’s GOV.UK Design System.
user5994461超过 3 年前
For reference, it&#x27;s 5 hours later now and it&#x27;s still online.
globular-toast超过 3 年前
How was this discovered and do we know how long it was in this state?
2-718-281-828超过 3 年前
american of course, russian always, japanese, chinese and thai - sure why not, heck, even danish or swedish ... but british or english - no way - not even once
aj7超过 3 年前
Hacker News crashed the website.